ñîâåðøåííî ñåêðåòíî ÐÎÌÀÍ ËÓÊÎÂÍÈÊΠ(LRB@SANDY.RU) Ñïåöâûïóñê: Õàêåð, íîìåð #072, ñòð. 072-010-7 Íî ñàìîãî ñåðòèôèêàòà äëÿ IPSec ó íàñ ïîêà íåò. Ïîëó÷èì åãî: 1 Ñ ÊÎÌÏÜÞÒÅÐÀ, ÍÀ ÊÎÒÎÐÎÌ ÒÐÅÁÓÅÒÑß ÓÑÒÀÍÎÂÈÒÜ ÑÅÐÒÈÔÈÊÀÒÛ,  ÀÄÐÅÑÍÎÉ ÑÒÐÎÊÅ ÍÀÁÈÐÀÅØÜ: HTTP://IP_ÖÅÍÒÐÀ_ÑÅÐÒ/CERTSRV. 2 ÂÛÁÈÐÀÅØÜ REQUEST A CERTIFICATE È ÆÌÅØÜ NEXT. 3 ÂÛÁÈÐÀÅØÜ ADVANCED REQUEST È ÆÌÅØÜ NEXT. 4 ÂÛÁÈÐÀÅØÜ SUBMIT A CERTIFICATE REQUEST TO THIS CA USING A FORM È ÆÌÅØÜ NEXT. 5 ÓÊÀÇÛÂÀÅØÜ ÏÀÐÀÌÅÒÐÛ ÇÀÏÐÎÑÀ. ÈÇ ÎÁßÇÀÒÅËÜÍÎÃÎ INTENDED PURPOSE ÂÛÁÈÐÀÅØÜ IPSEC CERTIFICATE (ÌÎÆÍÎ ÎÑÒÀÂÈÒÜ È CLIENT AUTHENTICATION CERTIFICATE, ÎÁËÀÑÒÜ ÅÃÎ ÏÐÈÌÅÍÅÍÈß ÁÎËÅÅ ØÈÐÎÊÀß). 6 ÂÛÁÈÐÀÅØÜ ÎÏÖÈÞ USE LOCAL MACHINE STORE, ÍÀÆÈÌÀÅØÜ ÍÀ SUBMIT È YES. Äàëüíåéøèå äåéñòâèÿ âûïîëíÿþòñÿ íà êîìïüþòåðå ñ óñòàíîâëåííûì óäîñòîâåðÿþùèì öåíòðîì: 7 ÈÇ ÏÀÏÊÈ ADMINISTRATIVE TOOLS ÎÒÊÐÛÂÀÅØÜ ÎÑÍÀÑÒÊÓ CERTIFICATION AUTHORITY. 8 ÎÒÊÐÛÂÀÅØÜ ÄÅÐÅÂÎ ÊÎÍÑÎËÈ, ÍÀÆÈÌÀß ÍÀ ÏËÞÑÈÊ, È ÂÛÁÈÐÀÅØÜ PENDING REQUESTS. 9  ÏÐÀÂÎÉ ÏÀÍÅËÈ ÍÀÕÎÄÈØÜ ÇÀÏÐÎÑ ÍÀ ÍÀØ ÑÅÐÒÈÔÈÊÀÒ, ÍÀ ÍÅÌ ÏÐÀÂÛÉ ÊËÈÊ, ALL TASKS È ISSUE. Òåïåðü ñ êîìïüþòåðà, ñ êîòîðîãî ñåðòèôèêàò çàïðàøèâàëñÿ, ìîæíî åãî ïîëó÷èòü. Äëÿ ýòîãî: 10 Ñ ÊÎÌÏÜÞÒÅÐÀ, ÍÀ ÊÎÒÎÐÎÌ ÒÐÅÁÓÅÒÑß ÓÑÒÀÍÎÂÈÒÜ ÑÅÐÒÈÔÈÊÀÒ,  ÀÄÐÅÑÍÎÉ ÑÒÐÎÊÅ ÍÀÁÈÐÀÅØÜ: HTTP://IP_ÖÅÍÒÐÀ_ÑÅÐÒ/CERTSRV. 11 ÂÛÁÈÐÀÅØÜ CHECK ON A PENDING CERTIFICATE, ÄÀËÅÅ NEXT. 12  ÎÊÍÅ PLEASE SELECT THE CERTIFICATE REQUEST YOU WANT TO CHECK ÄÎËÆÅÍ ÏÎßÂÈÒÜÑß ÑÅÐÒÈÔÈÊÀÒ. ÊËÈÊÀÅØÜ NEXT È ÂÛÁÈÐÀÅØÜ INSTALL THIS CERTIFICATE,  ÎÊÍÅ ÍÀÆÈÌÀÅØÜ YES. Ïðîâåðü, ÷òî â îñíàñòêå Certificate(Local Computer), â âåòâè Personal, Certificates ïîÿâèëñÿ ñåðòèôèêàò. ÅÑËÈ ÑÅÐÒÈÔÈÊÀÒ ÅÑÒÜ, ÍÎ ÎÒÎÁÐÀÆÀÅÒÑß ÎÍ ÊÀÊ ÍÅÄÅÉÑÒÂÈÒÅËÜÍÛÉ, ÏÐÎÂÅÐÜ, ÍÀÕÎÄÈÒÑß ËÈ ÑÈÑÒÅÌÍÎÅ ÂÐÅÌß ÍÀ ÊÎÌÏÜÞÒÅÐÅ Â ÏÐÎÌÅÆÓÒÊÅ ÂÀËÈÄÍÎÑÒÈ ÑÅÐÒÈÔÈÊÀÒÀ (ÒÎ ÅÑÒÜ ÂÎÇÌÎÆÍÎ, ÑÅÐÒÈÔÈÊÀÒ ÅÙÅ ÍÅ ÂÑÒÓÏÈË Â ÑÈËÓ ÈËÈ ÑÐÎÊ ÅÃÎ ÄÅÉÑÒÂÈß ÓÆÅ ÇÀÊÎÍ×ÈËÑß) Òåïåðü ïðîáóé îïÿòü óñòàíîâèòü IPSec-ñîåäèíåíèå. Òóííåëü äîëæåí ïîäíÿòüñÿ ñ àóòåíòèôèêàöèåé ñòîðîí ñ ïîìîùüþ ñåðòèôèêàòîâ. [òðàíñïîðòíûé ðåæèì.] [ñöåíàðèé 2] Îáåñïå÷èì øèôðîâàíèå òðàôèêà ìåæäó ôàéëîâûì ñåðâåðîì è êîìïüþòåðàìè â ëîêàëüíîé ñåòè, èñïîëüçóÿ IPSec â òðàíñïîðòíîì ðåæèìå. Äëÿ ôàéëîâîãî ñåðâåðà ðàçðåøè øèôðîâàííûé òðàôèê íà TCP/139 è TCP/445 ïîðòû è íåøèôðîâàííûå âõîäÿùèå ICMP-ïàêåòû. Âåñü îñòàëüíîé òðàôèê çàïðåòè. Íàñòðàèâàé ôàéëîâûé ñåðâåð (ðîóòèòü çäåñü íè÷åãî íå íóæíî, ïîýòîìó â êà÷åñòâå ñåðâåðà ïîäîéäåò êîìïüþòåð è ïîä óïðàâëåíèåì íå ñåðâåðíîé ïëàòôîðìû Windows): 1 ÌÅÍÞ START, ÄÀËÅÅ RUN, ÍÀÁÈÐÀÅØÜ SECPOL.MSC È ÍÀÆÈÌÀÅØÜ ENTER. 2 ÏÐÀÂÛÉ ÊËÈÊ ÍÀ IP SECURITY POLICIES ON LOCAL MACHINE, ÄÀËÅÅ ÊËÈÊ CREATE IP SECURITY POLICY. 3 ÊËÈÊÀÅØÜ NEXT. 4 ÏÈØÅØÜ ÈÌß ÍÎÂÎÉ ÏÎËÈÒÈÊÈ, ÍÀÏÐÈÌÅÐ «IPSEC FOR FILE SERVER», ÊËÈÊÀÅØÜ NEXT. 5 ÑÍÈÌÀÅØÜ ÃÀËÊÓ ACTIVATE THE DEFAULT RESPONSE RULE, ÊËÈÊÀÅØÜ NEXT. 6 ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ EDIT PROPERTIES, ÊËÈÊÀÅØÜ FINISH. 7 ÄÎÁÀÂËßÅØÜ ÏÐÀÂÈËÎ IPSEC, ÊËÈÊÀß ADD... 8 ÄÎÁÀÂËßÅØÜ IP FILTER, ÊËÈÊÀß ADD... 9 ÍÀÇÛÂÀÅØÜ ÔÈËÜÒÐ INBOUND SMB È ÍÀÆÈÌÀÅØÜ ADD... 10  SOURCE ADDRESS ÂÛÁÈÐÀÅØÜ A SPECIFIC IP SUBNET È ÏÈØÅØÜ ÀÄÐÅÑ È ÌÀÑÊÓ ÄËß ÑÅÒÈ «À»,  DESTINATION ADDRESS ÓÊÀÇÛÂÀÅØÜ IP_ÔÀÉË.ÑÅÐÂÅÐÀ. ÎÑÒÀÂËßÅØÜ ÎÏÖÈÞ MIRRORED. ALSO MATCH PACKETS WITH THE EXACT OPPOSITE SOURCE AND DESTINATION ADDRESSES. |